CVE-2018-7797
Last modified
CVE-2018-7797 is a vulnerability of currently unknown severity. A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Energy Expert | 1.3 |
| Schneider-Electric | Ecostruxure Energy Expert | 2.0 |
| Schneider-Electric | Ecostruxure Power Monitoring Expert | 8.2 |
| Schneider-Electric | Ecostruxure Power Monitoring Expert | 9.0 |
| Schneider-Electric | Ecostruxure Power Scada Operation | 8.2 |
| Schneider-Electric | Ecostruxure Power Scada Operation | 9.0 |
References
- http://www.securityfocus.com/bid/106277Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/106277Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7797?
How severe is CVE-2018-7797?
How do I fix CVE-2018-7797?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7791A Permissions, Privileges, and Access Control vulnerability …9.8
- CVE-2018-7792A Permissions, Privileges, and Access Control vulnerability …7.5
- CVE-2018-7793A Credential Management vulnerability exists in FoxView HMI …
- CVE-2018-7794A CWE-754: Improper Check for Unusual or Exceptional Conditi…7.5
- CVE-2018-7795A Cross Protocol Injection vulnerability exists in Schneider…5.4
- CVE-2018-7796A Buffer Error vulnerability exists in PowerSuite 2, all rel…
- CVE-2018-7798A Insufficient Verification of Data Authenticity (CWE-345) v…8.2
- CVE-2018-7799A DLL hijacking vulnerability exists in Schneider Electric S…
- CVE-2018-7800A Hard-coded Credentials vulnerability exists in EVLink Park…
- CVE-2018-7801A Code Injection vulnerability exists in EVLink Parking, v3.…8.8
- CVE-2018-7802A SQL Injection vulnerability exists in EVLink Parking, v3.2…
- CVE-2018-7803A CWE-754 Improper Check for Unusual or Exceptional Conditio…
Are you affected by CVE-2018-7797?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
